
The Tycoon2FA phishing service, which Europol and its partners took down on March 4, has rebounded to its previous activity levels.
Microsoft spearheaded the takedown, which involved confiscating 330 domains that were essential to Tycoon2FA’s operation. These domains included control panels and fake login pages used in attacks.
However, the disruption by law enforcement was brief, as CrowdStrike observed the cybercrime service returning to its typical operational scale within a few days.
“Falcon Complete noticed a temporary decline in Tycoon2FA campaign activity after the takedown, with daily activity on March 4 and 5, 2026, dropping to 25% of what it was before,” CrowdStrike stated in their report.
“However, activity soon bounced back to pre-disruption levels, with daily cloud compromise remediations returning to levels seen in early 2026.”
Tycoon2FA, initially identified by Sekoia about two years ago, surfaced as a phishing-as-a-service (PhaaS) platform. It specializes in targeting Microsoft 365 and Gmail accounts, using techniques to bypass two-factor authentication (2FA).
A month later, Trustwave noted that Tycoon2FA’s developers were actively improving the platform, introducing new and improved features to attract more cybercriminals.
Tycoon2FA is a major player in phishing, with Microsoft reporting that it generated 30 million phishing emails monthly, representing 62% of all emails blocked by the company.
CrowdStrike reports that Tycoon2FA is active again, employing largely unchanged methods and procedures. It supports various illegal activities, including business email compromise (BEC), email thread hijacking, cloud account breaches, and malicious SharePoint links.
Since the disruption, Tycoon2FA has been involved in malicious email campaigns that use harmful URLs, URL shortening services, legitimate platforms (like presentation tools) with misused redirection features, and compromised websites.
Notably, some of the original infrastructure stayed online, indicating that the disruption was not complete. New phishing domains and IP addresses were quickly registered following the law enforcement action.
Observed post-compromise activity includes creating inbox rules, hiding folders for fraudulent emails, and preparing for BEC attacks.
In conclusion, CrowdStrike states that without arrests or physical asset seizures, it’s simple for cybercriminals to restore and replace the affected infrastructure. As long as there’s high demand in the phishing world, the incentive for PhaaS platform operators remains unchanged.
#after #back #intervene; #news #phishing #platforms #police #return. #sites #tycoon2fa — News
© Bulletproof Servers. All rights reserved.